<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="https://community.appian.com/cfs-file/__key/system/syndication/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Integration of Appian with keyclock</title><link>https://community.appian.com/discussions/f/integrations/20693/integration-of-appian-with-keyclock</link><description>We would like to implement authorization using keycloak in Appian. Can anyone suggest anything</description><dc:language>en-US</dc:language><generator>Telligent Community 12</generator><item><title>RE: Integration of Appian with keyclock</title><link>https://community.appian.com/thread/80664?ContentTypeID=1</link><pubDate>Thu, 01 Apr 2021 15:23:45 GMT</pubDate><guid isPermaLink="false">d3a83456-d57b-489c-a84c-4e8267bb592a:faaad890-f4bf-4cd5-80c7-c7ac09323640</guid><dc:creator>juergeng393</dc:creator><description>&lt;p&gt;Hi,&lt;br /&gt;you just follow the documentation here:&lt;br /&gt;&lt;a href="https://docs.appian.com/suite/help/21.1/Appian_Administration_Console.html#saml-authentication"&gt;https://docs.appian.com/suite/help/21.1/Appian_Administration_Console.html#saml-authentication&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="https://docs.appian.com/suite/help/21.1/SAML_for_Single_Sign-On.html#how-to-add-a-saml-identity-provider"&gt;https://docs.appian.com/suite/help/21.1/SAML_for_Single_Sign-On.html#how-to-add-a-saml-identity-provider&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;You can just add another SAML Identity provider. And of course you might specify the landing page for the external users in the Admin Console based on their group membership. The SAM assertions supports now the group attribute.&lt;/p&gt;
&lt;p&gt;&lt;a href="https://docs.appian.com/suite/help/21.1/Appian_Administration_Console.html#user-start-pages"&gt;https://docs.appian.com/suite/help/21.1/Appian_Administration_Console.html#user-start-pages&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;You might have to consider the overall architecture of the Appian Platform. Not sure if you are on premise or on cloud. The load balancer you are using has to be configured exposing the Appian Platform with an external IP. You might consider to put a rule into your Web Application Firewall (WAF) to prevent the external URL is accessible for the public. Even if you are on the Cloud already that might be a good idea.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Integration of Appian with keyclock</title><link>https://community.appian.com/thread/80635?ContentTypeID=1</link><pubDate>Thu, 01 Apr 2021 08:09:34 GMT</pubDate><guid isPermaLink="false">d3a83456-d57b-489c-a84c-4e8267bb592a:363dbf8a-92e6-4d83-8198-3615d434f3c4</guid><dc:creator>bihitakdass</dc:creator><description>&lt;p&gt;Hi Juergeng&lt;/p&gt;
&lt;p&gt;Thanks for the inputs, our requirement for SSO is as follows.&lt;/p&gt;
&lt;p&gt;1. We have users internal to our organization in which we are already using Appian inbuilt SAML 2.0 with our organization infrastructure to authenticate with SSO during Appian accessing of sites and tempos.&lt;/p&gt;
&lt;p&gt;2. We have to implement&amp;nbsp;&lt;span&gt;Keycloak for our external users which are not in our organization so that they can be authenticated using SSO in Appian.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;Since we are already using the SAML 2.0 of Appian for our internal organization users , how can we leverage&amp;nbsp;the same for &amp;quot;Keycloak&amp;quot; for external users.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;Please help!!&lt;/span&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Integration of Appian with keyclock</title><link>https://community.appian.com/thread/80624?ContentTypeID=1</link><pubDate>Wed, 31 Mar 2021 18:14:30 GMT</pubDate><guid isPermaLink="false">d3a83456-d57b-489c-a84c-4e8267bb592a:37e08165-5007-4d5b-8b66-7db9375aa15a</guid><dc:creator>juergeng393</dc:creator><description>&lt;p&gt;To make a suggestion depends on knowledge about your infrastructure. What kind of protocol you are trying to use?&lt;br /&gt;SAML 2.0?&lt;br /&gt;Then the approach should be pretty much forward.&amp;nbsp;&lt;br /&gt;1. Install the Keycloak Servers&lt;br /&gt;2. Establish the SSO with the Keycloak Servers - e.g. connection to LDAP etc.&lt;br /&gt;3. Configure Appian for SAML 2.0 usage at the Admin Page referring to the Keycloak URL&lt;/p&gt;
&lt;p&gt;Following both documentions - Appian and Keycloak - it should be possible&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item></channel></rss>